Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Content] 8.3 Add Investigation Guides - 3 #1990

Merged
merged 6 commits into from
May 31, 2022

Conversation

w0rk3r
Copy link
Contributor

@w0rk3r w0rk3r commented May 23, 2022

Summary

Adds Investigation guides to the following rules:

  • Clearing Windows Console History
  • Clearing Windows Event Log
  • Windows Event Logs Cleared
  • Disable Windows Event and Security Logs Using Built-in Tools
  • Enable Host Network Discovery via Netsh
  • Windows Firewall Disabled via PowerShell
  • Execution of File Written or Modified by Microsoft Office
  • Execution of File Written or Modified by PDF Reader
  • Potential Lateral Tool Transfer via SMB Share (Renamed from: "Lateral Tool Transfer")
  • Account configured with never Expiring Password

Copy link
Contributor

@terrancedejesus terrancedejesus left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving so it is ready to merge when needed.

Copy link
Contributor

@nastasha-solomon nastasha-solomon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left some comments for your consideration. Thanks for your work on this @w0rk3r !

@w0rk3r
Copy link
Contributor Author

w0rk3r commented May 31, 2022

Hey @nastasha-solomon & @joepeeples, can I get a final review on this one to merge?

@w0rk3r w0rk3r requested a review from nastasha-solomon May 31, 2022 10:24
Copy link
Contributor

@joepeeples joepeeples left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a few small suggestions, but otherwise LGTM!

@w0rk3r w0rk3r merged commit 27f5c2e into main May 31, 2022
@w0rk3r w0rk3r deleted the investigation_guides_8.3_3 branch May 31, 2022 15:57
protectionsmachine pushed a commit that referenced this pull request May 31, 2022
* [Security Content] 8.3 Add Investigation Guides - 3

* bump date

* Apply suggestions from code review

Co-authored-by: nastasha-solomon <[email protected]>

* Apply suggestions from code review

Co-authored-by: Joe Peeples <[email protected]>

Co-authored-by: nastasha-solomon <[email protected]>
Co-authored-by: Joe Peeples <[email protected]>

(cherry picked from commit 27f5c2e)
protectionsmachine pushed a commit that referenced this pull request May 31, 2022
* [Security Content] 8.3 Add Investigation Guides - 3

* bump date

* Apply suggestions from code review

Co-authored-by: nastasha-solomon <[email protected]>

* Apply suggestions from code review

Co-authored-by: Joe Peeples <[email protected]>

Co-authored-by: nastasha-solomon <[email protected]>
Co-authored-by: Joe Peeples <[email protected]>

(cherry picked from commit 27f5c2e)
protectionsmachine pushed a commit that referenced this pull request May 31, 2022
* [Security Content] 8.3 Add Investigation Guides - 3

* bump date

* Apply suggestions from code review

Co-authored-by: nastasha-solomon <[email protected]>

* Apply suggestions from code review

Co-authored-by: Joe Peeples <[email protected]>

Co-authored-by: nastasha-solomon <[email protected]>
Co-authored-by: Joe Peeples <[email protected]>

(cherry picked from commit 27f5c2e)
protectionsmachine pushed a commit that referenced this pull request May 31, 2022
* [Security Content] 8.3 Add Investigation Guides - 3

* bump date

* Apply suggestions from code review

Co-authored-by: nastasha-solomon <[email protected]>

* Apply suggestions from code review

Co-authored-by: Joe Peeples <[email protected]>

Co-authored-by: nastasha-solomon <[email protected]>
Co-authored-by: Joe Peeples <[email protected]>

(cherry picked from commit 27f5c2e)
protectionsmachine pushed a commit that referenced this pull request May 31, 2022
* [Security Content] 8.3 Add Investigation Guides - 3

* bump date

* Apply suggestions from code review

Co-authored-by: nastasha-solomon <[email protected]>

* Apply suggestions from code review

Co-authored-by: Joe Peeples <[email protected]>

Co-authored-by: nastasha-solomon <[email protected]>
Co-authored-by: Joe Peeples <[email protected]>

(cherry picked from commit 27f5c2e)
protectionsmachine pushed a commit that referenced this pull request May 31, 2022
* [Security Content] 8.3 Add Investigation Guides - 3

* bump date

* Apply suggestions from code review

Co-authored-by: nastasha-solomon <[email protected]>

* Apply suggestions from code review

Co-authored-by: Joe Peeples <[email protected]>

Co-authored-by: nastasha-solomon <[email protected]>
Co-authored-by: Joe Peeples <[email protected]>

(cherry picked from commit 27f5c2e)
protectionsmachine pushed a commit that referenced this pull request May 31, 2022
* [Security Content] 8.3 Add Investigation Guides - 3

* bump date

* Apply suggestions from code review

Co-authored-by: nastasha-solomon <[email protected]>

* Apply suggestions from code review

Co-authored-by: Joe Peeples <[email protected]>

Co-authored-by: nastasha-solomon <[email protected]>
Co-authored-by: Joe Peeples <[email protected]>

(cherry picked from commit 27f5c2e)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule Security Content
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants